ThreatCluster

Multiple Vulnerabilities in Microsoft Dynamics 365 Field Service Identified

First seen 12 Nov 2025, 21:25 UTC Api.Msrc.Microsoft 37

Article Content

Browse articles
ThreatCluster

Two spoofing vulnerabilities (CVE-2025-62211 and CVE-2025-62210) have been identified in Dynamics 365 Field Service (online), allowing authorized attackers to perform spoofing via improper input neutralization during web page generation. Additionally, CVE-2025-62206 exposes sensitive information in Dynamics 365 (on-premises) to unauthorized actors over a network.